Policy Home Page - Detail Page
8635 - INFORMATION AND DATA PRIVACY SECURITY, BREACH AND NOTIFICATIONPrint PolicyPRINT THIS DOCUMENT
8000 - SUPPORT SERVICES
8635 INFORMATION AND DATA PRIVACY SECURITY, BREACH AND NOTIFICATION
Last Updated Date: 10/22/2020
Revisions History: 10/22/2020
Related Policies & Documents: 1120, 5500, 5500R, 8630, 8635R, 8635E1, 8635E2, 8635E3
The Board of Education acknowledges the heightened concern regarding the rise in identity theft and the need for secure networks and prompt notification when security breaches occur. Thus, the Board adopts the National Institute for Standards and Technology Cybersecurity Framework Version 1.1 (NIST CSF) for data security and protection. The Data Protection Officer is responsible for ensuring the District’s systems follow NIST CSF and adopt technologies, safeguards and practices which align with it. This will include an assessment of the District’s current cybersecurity state, their target future cybersecurity state, opportunities for improvement, progress toward the target state, and communication about cyber security risk.
The Board will designate a Data Protection Officer to be responsible for the implementation of the policies and procedures required in Education Law §2-d and its accompanying regulations, and to serve as the point of contact for data security and privacy District.
The Board directs the Superintendent, in accordance with appropriate business and technology personnel, and the Data Protection Officer (where applicable) to establish regulations which address:
· The protections of “personally identifiable information” or PPI of student and teachers/Building Principals under Education Law §2-d and Part 121 of the Commissioner of Education.
· The protections of “private information” under State Technology Law §208 and the NY SHIELD Act; and
· Procedures to notify persons affected by breaches or unauthorized access of protected information.
I. Student and Teacher/Building Principal “Personally Identifiable Information” under Education Law §2-d
A. General Provisions
PII as applied to student data is as defined in Family Educational Rights and Privacy Act (Policy 5500 – Student Records), which includes certain types of information that could identify a student, and is listed in Regulation 8635-R. PII as applied to teacher and Building Principal data, means results of Annual Professional Performance Reviews that identify the individual teachers and Building Principals, which are confidential under Education Law §§3012-c and 3012-d, except where required to be disclosed under state law and regulations.
The Data Protection Officer will see that every use and disclosure of PII by the District benefits students and the District (e.g., improve academic achievement, empower parents/guardians and students with information, and/or advance efficient and effective school operations). However, PII will not be included in public reports or other documents.
The District will protect the confidentiality of student and teacher/Building Principal PII while stored or transferred using industry standard safeguards and best practices, such as encryption, firewalls, and passwords. The District will monitor its data systems, develop incident response plans, limit access to PII to District employees and third-party contractors who need such access to fulfill their professional responsibilities or contractual obligations, and destroy PII when it is no longer needed.
Certain federal laws and regulations provide additional rights regarding confidentiality of and access to student records, as well as permitted disclosures without consent, which are addressed in Policy 5500 and Regulation 5500-R - Student Records.
Under no circumstances will the District sell PII. It will not disclose PII for any marketing or commercial purpose, facilitate its use or disclosure by any other party for any marketing or commercial purpose, or permit another party to do so. Further, the District will take steps to minimize the collection, processing, and transmission of PII.
Except as required by law or in the case of enrollment data, the District will not report the following student data to the State Education Department:
1. Juvenile delinquency records
2. Criminal records
3. Medical and health records, and
4. Student biometric information
The District has created and adopted a Parent’s Bill of Rights for Data Privacy and Security (see Exhibit 8635-E). It has been published on the District’s website at www.manhassetschools.org and can be requested from the District Clerk.
B. Third-party Contractors
The District will ensure that contracts with third-party contractors reflect that confidentiality of any student and/or teacher or Building Principal PII be maintained in accordance with federal and state law and the District's data security and privacy policy.
Each third-party contractor that will receive student data or teacher or Building Principal data must:
1. Adopt technologies, safeguards and practices that align with the NIST CSF.
2. Comply with the District’s data security and privacy policy and applicable laws impacting the District.
3. Limit internal access to PII to only those employees or sub-contractors that need access to provide the contracted services.
4. Not use the PII for any purpose not explicitly authorized in its contract.
5. Not disclose any PII to any other party without the prior written consent of the parent/guardian or eligible student (i.e., students who are eighteen (18) years old or older):
i. Except for authorized representatives of the third-party contractor to the extent they are carrying out the contract; or
ii. Unless required by statute or court order and the third-party contractor provides notice of disclosure to the District, unless expressly prohibited.
6. Maintain reasonable administrative, technical, and physical safeguards to protect the security, confidentiality, and integrity of PII in its custody.
7. Use encryption to protect PII in its custody; and
8. Not sell, use, or disclose PII for any marketing or commercial purpose, facilitate its use or disclosure by others for marketing or commercial purpose, or permit another party to do so. Third party contractors may release PII to subcontractors engaged to perform the contractor’s obligations, but such subcontractors must abide by data protection obligations of state and federal law, and the contract with the District.
If the third-party contractor has a breach or unauthorized release of PII, it will promptly notify the District in the most expedient way possible without unreasonable delay but no more than seven (7) calendar days after the breach’s discovery.
C. Third-Party Contractors’ Data Security and Privacy Plan
The District will ensure that contracts with all third-party contractors include the third-party contractor’s data security and privacy plan. This plan must be accepted by the District.
At a minimum, each plan will:
1. Outline how all state, federal, and local data security and privacy contract requirements over the life of the contract will be met, consistent with this policy.
2. Specify the safeguards and practices it has in place to protect PII.
3. Demonstrate that it complies with the requirements of Section 121.3(c) of this Part.
4. Specify how those who have access to student and/or teacher or Building Principal data receive or will receive training on the federal and state laws governing confidentiality of such data prior to receiving access.
5. Specify if the third-party contractor will utilize sub-contractors and how it will manage those relationships and contracts to ensure personally identifiable information is protected.
6. Specify how the third-party contractor will manage data security and privacy incidents that implicate personally identifiable information (PII) including specifying any plans to identify breaches and unauthorized disclosures, and to promptly notify the District.
7. Describe if, how and when data will be returned to the District, transitioned to a successor contractor, at the District’s direction, deleted or destroyed by the third-party contractor when the contract is terminated or expires.
D. Training
The District will provide annual training on data privacy and security awareness to all employees who have access to student and teacher/Building Principal PII.
E. Reporting
Any breach of the District’s information storage or computerized data which compromises the security, confidentiality, or integrity of student or teacher/Building Principal PII maintained by the District will be promptly reported to the Data Protection Officer, the Superintendent and the Board of Education.
F. Notifications
The Data Protection Officer will report every discovery or report of a breach or unauthorized release of student, teacher or Building Principal PII to the State’s Chief Privacy Officer without unreasonable delay, but no more than ten (10) calendar days after such discovery.
The District will notify affected parents/guardians, eligible students, teachers and/or Building Principals in the most expedient way possible and without unreasonable delay, but no more than sixty (60) calendar days after the discovery of a breach or unauthorized release or third-party contractor notification.
However, if notification would interfere with an ongoing law enforcement investigation, or cause further disclosure of PII by disclosing an unfixed security vulnerability, the District will notify parents/guardians, eligible students, teachers and/or Building Principals within seven (7) calendar days after the security vulnerability has been remedied, or the risk of interference with the law enforcement investigation ends.
The Superintendent, or designee, in consultation with the Data Protection Officer, will establish procedures to provide notification of a breach or unauthorized release of student, teacher or Building Principal PII, and establish and communicate to parents/guardians, eligible students, and District staff a process for filing complaints about breaches or unauthorized releases of student and teacher/Building Principal PII.
II. “Private Information” under State Technology Law §208
“Private information” is defined in State Technology Law §208, and includes certain types of information, outlined in the accompanying regulation, which would put an individual at risk for identity theft or permit access to private accounts. “Private information” does not include information that can lawfully be made available to the public pursuant to federal or state law or regulation.
Any breach of the District’s information storage or computerized data which compromises the security, confidentiality, or integrity of “private information” maintained by the District must be promptly reported to the Superintendent and the Board.
The Board directs the Superintendent, in accordance with appropriate business and technology personnel, to establish regulations which:
· Identify and/or define the types of private information that is to be kept secure.
· Include procedures to identify any breaches of security that result in the release of private information; and
· Include procedures to notify persons affected by the security breach as required by law.
III. Employee “Personal Identifying Information” under Labor Law § 203-d
Pursuant to Labor Law §203-d, the District will not communicate employee “personal identifying information” to the public. This includes:
1. Social security number
2. Home address or telephone number
3. Personal email address
4. Internet identification name or password
5. Parent’s surname prior to marriage; and
6. Drivers’ license number
In addition, the District will protect employee social security numbers in that such numbers will not be:
1. Publicly posted or displayed
2. Visibly printed on any ID badge, card, or timecard
3. Placed in files with unrestricted access; or
4. Used for occupational licensing purposes
Employees with access to such information will be notified of these prohibitions and their obligations.
Policy References
State Technology Law §§201-208
Labor Law §203-d
Education Law §2-d
8 NYCRR Part 121
8000 - SUPPORT SERVICES
8635 INFORMATION AND DATA PRIVACY SECURITY, BREACH AND NOTIFICATION
Last Updated Date: 10/22/2020
Revisions History: 10/22/2020
Related Policies & Documents: 1120, 5500, 5500R, 8630, 8635R, 8635E1, 8635E2, 8635E3
The Board of Education acknowledges the heightened concern regarding the rise in identity theft and the need for secure networks and prompt notification when security breaches occur. Thus, the Board adopts the National Institute for Standards and Technology Cybersecurity Framework Version 1.1 (NIST CSF) for data security and protection. The Data Protection Officer is responsible for ensuring the District’s systems follow NIST CSF and adopt technologies, safeguards and practices which align with it. This will include an assessment of the District’s current cybersecurity state, their target future cybersecurity state, opportunities for improvement, progress toward the target state, and communication about cyber security risk.
The Board will designate a Data Protection Officer to be responsible for the implementation of the policies and procedures required in Education Law §2-d and its accompanying regulations, and to serve as the point of contact for data security and privacy District.
The Board directs the Superintendent, in accordance with appropriate business and technology personnel, and the Data Protection Officer (where applicable) to establish regulations which address:
· The protections of “personally identifiable information” or PPI of student and teachers/Building Principals under Education Law §2-d and Part 121 of the Commissioner of Education.
· The protections of “private information” under State Technology Law §208 and the NY SHIELD Act; and
· Procedures to notify persons affected by breaches or unauthorized access of protected information.
I. Student and Teacher/Building Principal “Personally Identifiable Information” under Education Law §2-d
A. General Provisions
PII as applied to student data is as defined in Family Educational Rights and Privacy Act (Policy 5500 – Student Records), which includes certain types of information that could identify a student, and is listed in Regulation 8635-R. PII as applied to teacher and Building Principal data, means results of Annual Professional Performance Reviews that identify the individual teachers and Building Principals, which are confidential under Education Law §§3012-c and 3012-d, except where required to be disclosed under state law and regulations.
The Data Protection Officer will see that every use and disclosure of PII by the District benefits students and the District (e.g., improve academic achievement, empower parents/guardians and students with information, and/or advance efficient and effective school operations). However, PII will not be included in public reports or other documents.
The District will protect the confidentiality of student and teacher/Building Principal PII while stored or transferred using industry standard safeguards and best practices, such as encryption, firewalls, and passwords. The District will monitor its data systems, develop incident response plans, limit access to PII to District employees and third-party contractors who need such access to fulfill their professional responsibilities or contractual obligations, and destroy PII when it is no longer needed.
Certain federal laws and regulations provide additional rights regarding confidentiality of and access to student records, as well as permitted disclosures without consent, which are addressed in Policy 5500 and Regulation 5500-R - Student Records.
Under no circumstances will the District sell PII. It will not disclose PII for any marketing or commercial purpose, facilitate its use or disclosure by any other party for any marketing or commercial purpose, or permit another party to do so. Further, the District will take steps to minimize the collection, processing, and transmission of PII.
Except as required by law or in the case of enrollment data, the District will not report the following student data to the State Education Department:
1. Juvenile delinquency records
2. Criminal records
3. Medical and health records, and
4. Student biometric information
The District has created and adopted a Parent’s Bill of Rights for Data Privacy and Security (see Exhibit 8635-E). It has been published on the District’s website at www.manhassetschools.org and can be requested from the District Clerk.
B. Third-party Contractors
The District will ensure that contracts with third-party contractors reflect that confidentiality of any student and/or teacher or Building Principal PII be maintained in accordance with federal and state law and the District's data security and privacy policy.
Each third-party contractor that will receive student data or teacher or Building Principal data must:
1. Adopt technologies, safeguards and practices that align with the NIST CSF.
2. Comply with the District’s data security and privacy policy and applicable laws impacting the District.
3. Limit internal access to PII to only those employees or sub-contractors that need access to provide the contracted services.
4. Not use the PII for any purpose not explicitly authorized in its contract.
5. Not disclose any PII to any other party without the prior written consent of the parent/guardian or eligible student (i.e., students who are eighteen (18) years old or older):
i. Except for authorized representatives of the third-party contractor to the extent they are carrying out the contract; or
ii. Unless required by statute or court order and the third-party contractor provides notice of disclosure to the District, unless expressly prohibited.
6. Maintain reasonable administrative, technical, and physical safeguards to protect the security, confidentiality, and integrity of PII in its custody.
7. Use encryption to protect PII in its custody; and
8. Not sell, use, or disclose PII for any marketing or commercial purpose, facilitate its use or disclosure by others for marketing or commercial purpose, or permit another party to do so. Third party contractors may release PII to subcontractors engaged to perform the contractor’s obligations, but such subcontractors must abide by data protection obligations of state and federal law, and the contract with the District.
If the third-party contractor has a breach or unauthorized release of PII, it will promptly notify the District in the most expedient way possible without unreasonable delay but no more than seven (7) calendar days after the breach’s discovery.
C. Third-Party Contractors’ Data Security and Privacy Plan
The District will ensure that contracts with all third-party contractors include the third-party contractor’s data security and privacy plan. This plan must be accepted by the District.
At a minimum, each plan will:
1. Outline how all state, federal, and local data security and privacy contract requirements over the life of the contract will be met, consistent with this policy.
2. Specify the safeguards and practices it has in place to protect PII.
3. Demonstrate that it complies with the requirements of Section 121.3(c) of this Part.
4. Specify how those who have access to student and/or teacher or Building Principal data receive or will receive training on the federal and state laws governing confidentiality of such data prior to receiving access.
5. Specify if the third-party contractor will utilize sub-contractors and how it will manage those relationships and contracts to ensure personally identifiable information is protected.
6. Specify how the third-party contractor will manage data security and privacy incidents that implicate personally identifiable information (PII) including specifying any plans to identify breaches and unauthorized disclosures, and to promptly notify the District.
7. Describe if, how and when data will be returned to the District, transitioned to a successor contractor, at the District’s direction, deleted or destroyed by the third-party contractor when the contract is terminated or expires.
D. Training
The District will provide annual training on data privacy and security awareness to all employees who have access to student and teacher/Building Principal PII.
E. Reporting
Any breach of the District’s information storage or computerized data which compromises the security, confidentiality, or integrity of student or teacher/Building Principal PII maintained by the District will be promptly reported to the Data Protection Officer, the Superintendent and the Board of Education.
F. Notifications
The Data Protection Officer will report every discovery or report of a breach or unauthorized release of student, teacher or Building Principal PII to the State’s Chief Privacy Officer without unreasonable delay, but no more than ten (10) calendar days after such discovery.
The District will notify affected parents/guardians, eligible students, teachers and/or Building Principals in the most expedient way possible and without unreasonable delay, but no more than sixty (60) calendar days after the discovery of a breach or unauthorized release or third-party contractor notification.
However, if notification would interfere with an ongoing law enforcement investigation, or cause further disclosure of PII by disclosing an unfixed security vulnerability, the District will notify parents/guardians, eligible students, teachers and/or Building Principals within seven (7) calendar days after the security vulnerability has been remedied, or the risk of interference with the law enforcement investigation ends.
The Superintendent, or designee, in consultation with the Data Protection Officer, will establish procedures to provide notification of a breach or unauthorized release of student, teacher or Building Principal PII, and establish and communicate to parents/guardians, eligible students, and District staff a process for filing complaints about breaches or unauthorized releases of student and teacher/Building Principal PII.
II. “Private Information” under State Technology Law §208
“Private information” is defined in State Technology Law §208, and includes certain types of information, outlined in the accompanying regulation, which would put an individual at risk for identity theft or permit access to private accounts. “Private information” does not include information that can lawfully be made available to the public pursuant to federal or state law or regulation.
Any breach of the District’s information storage or computerized data which compromises the security, confidentiality, or integrity of “private information” maintained by the District must be promptly reported to the Superintendent and the Board.
The Board directs the Superintendent, in accordance with appropriate business and technology personnel, to establish regulations which:
· Identify and/or define the types of private information that is to be kept secure.
· Include procedures to identify any breaches of security that result in the release of private information; and
· Include procedures to notify persons affected by the security breach as required by law.
III. Employee “Personal Identifying Information” under Labor Law § 203-d
Pursuant to Labor Law §203-d, the District will not communicate employee “personal identifying information” to the public. This includes:
1. Social security number
2. Home address or telephone number
3. Personal email address
4. Internet identification name or password
5. Parent’s surname prior to marriage; and
6. Drivers’ license number
In addition, the District will protect employee social security numbers in that such numbers will not be:
1. Publicly posted or displayed
2. Visibly printed on any ID badge, card, or timecard
3. Placed in files with unrestricted access; or
4. Used for occupational licensing purposes
Employees with access to such information will be notified of these prohibitions and their obligations.
Policy References
State Technology Law §§201-208
Labor Law §203-d
Education Law §2-d
8 NYCRR Part 121